Six Takeaways from Sumsub APAC Multiverse 2026 on Governing Agentic AI

Agentic AI is advancing faster than the systems organisations use to explain, audit and govern its decisions. At Sumsub APAC Multiverse 2026, a new nine-market benchmark and industry panel showed that the next phase of adoption will depend on closing the traceability gap, proving agent authority and making accountability operational across the business.

Blackbox Research’s Chief Innovation Officer, Jon Smetherham, joined representatives from Sumsub, the Singapore FinTech Association and Visa to discuss how companies across Asia Pacific are preparing for AI systems that can act, transact and make decisions with increasing independence.

Here are six takeaways from the discussion.

1. Traceability is becoming the weakest link in AI governance

The study assessed organisational maturity through three pillars: autonomy, responsibility and traceability.

Autonomy measures how far AI can act independently. Responsibility considers whether an organisation has clearly assigned ownership for the outcomes. Traceability asks whether teams can reconstruct, explain and audit what an AI system did.

Across every market covered in the study, traceability lagged behind the other two pillars.

This creates what Sumsub described as an “accountability asymmetry”. Organisations are increasing the authority given to AI agents, while the infrastructure needed to investigate their actions is developing more slowly.

The business risk is straightforward. When an agent produces an unexpected result, leaders need to determine whether the cause was flawed data, an inappropriate instruction, system manipulation or an incorrect model output. Without reliable logs and continuous monitoring, that investigation can become slow, inconclusive or impossible.

The immediate priority is therefore to ensure that every increase in agent autonomy is matched by a corresponding increase in observability, testing and auditability.

2. Singapore’s lower score may reflect greater rigour rather than weaker capability

Singapore recorded an overall governance score of 65.6, placing it below several regional markets in the benchmark. For a jurisdiction widely regarded as a leading financial and technology centre, the result initially appeared counterintuitive.

The panel offered a more nuanced interpretation.

Singapore organisations may be assessing themselves against stricter and more practical standards. Rather than relying entirely on written policies, companies can benchmark themselves against established frameworks, technical tests and clearly defined governance expectations.

This may make respondents more conscious of their remaining gaps. A lower self-assessment can therefore indicate greater scrutiny, particularly when organisations are measuring themselves against what good governance should look like in operation.

The lesson for regional comparisons is that maturity scores require context. A confident rating may reflect genuine capability, a lower standard of evaluation or limited visibility of the risks. The score alone cannot answer which of these is true.

3. Commercial requirements may change behaviour faster than regulation

One of the most striking examples came from the Philippines, where 73% of respondents said their organisations conducted AI governance audits.

According to the discussion, many of these audits were driven by outsourcing contracts and client requirements. Businesses were being asked to prove that appropriate controls existed before they could secure or retain commercial relationships.

The comparison with e-commerce and marketplace companies was instructive. Although the sector uses AI extensively, only 39% reported conducting independent checks.

Regulation remains essential because it establishes common expectations and minimum protections. Commercial pressure can accelerate implementation by connecting governance directly to revenue.

When audit logs, traceability or recognised assessment frameworks become requirements for closing a deal, governance moves from a policy discussion to a market-access issue.

 

Blackbox in Action: Turning AI governance into a measurable benchmark

Blackbox co-conducted the research presented at the event, helping to assess how organisations across nine APAC markets and four sectors perform on autonomy, responsibility and traceability. This benchmarking approach allows leaders to move beyond general confidence in AI and identify where governance is operationally weakest, whether across markets, industries or individual stages of an AI-enabled workflow.

 

4. Agentic payments will progress from low-risk tasks to higher-stakes decisions

Consumers may be comfortable asking an AI agent to monitor the price of an airline ticket. Far fewer are ready to tell it to complete the purchase without approval.

That gap illustrates how agentic commerce is likely to develop.

Agents will initially gain autonomy in repetitive, low-value and easily reversible transactions. Higher-value purchases, complex financial decisions and transactions involving multiple conditions will continue to require human approval.

This is partly a consumer trust challenge and partly an infrastructure problem. Most websites, checkout systems and security controls were designed around human users. Businesses must now distinguish legitimate agents acting with customer permission from malicious bots attempting to exploit a system.

For the foreseeable future, human involvement will remain an important part of payment journeys. The level and timing of that involvement should depend on transaction value, reversibility, risk and the clarity of the consumer’s instructions.

5. “Know Your Agent” is emerging as a new trust requirement

Financial services spent decades developing Know Your Customer and Know Your Business processes. Agentic commerce introduces an additional question: how does an organisation know which agent is interacting with its systems, who authorised it and what it is permitted to do?

A credible “Know Your Agent” model would need to verify more than an agent’s technical identity. It should establish the individual or organisation the agent represents, the boundaries of its authority and the conditions under which that authority can be withdrawn.

This becomes more complicated as agents interact with other agents across different organisations and jurisdictions.

Interoperability will therefore be central to the next stage of AI governance. Companies cannot develop isolated approaches to agent identity, permissions and accountability when their systems will increasingly interact with external agents.

Common standards will require collaboration between technology providers, financial institutions, industry associations, regulators and the businesses deploying agents.

6. AI accountability must operate across the enterprise

The panel cautioned against treating AI as a standalone technology programme owned entirely by a Chief AI Officer, data team or innovation function.

AI is an enabler within products, processes and customer relationships. Its governance consequently cuts across leadership, product, technology, legal, compliance, risk and operations.

Visa’s contribution framed this through three areas: people, process and product. Organisations need people who understand the technology, processes that can use it safely and reliable data foundations before AI can be embedded into customer-facing products.

Specialist leaders can act as champions and coordinators. Ultimate responsibility remains distributed across the organisation.

The practical action is to establish cross-functional ownership before autonomy scales. Businesses should define agent permissions, identify where human approval is required, maintain reconstructable decision records and test whether their controls work during execution.


Trust will be built at the point of action

The central message from Sumsub APAC Multiverse 2026 was that governance can no longer rely on periodic reviews and static checklists.

Agentic AI makes decisions continuously. Its controls, monitoring and accountability mechanisms must operate continuously as well.

Organisations that can prove how their agents act, explain why decisions were made and intervene when necessary will be better positioned to earn the confidence of customers, partners and regulators. As agentic AI scales, traceability will become part of the product, the customer experience and the commercial proposition.


Ready to Make Agentic AI Work for You?

Reach out to Blackbox for a conversation on how our research solutions can help you build, market or regulate agentic products more effectively.

connect@blackbox.com.sg

Next
Next

Singapore–JB RTS Link: Why Singapore Needs a Two-City Strategy